Cyber Incident Response Engineer

Luxoft

Greater London

On-site

GBP 50,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Luxoft is looking for a Cyber Threat Intelligence expert in Greater London. The role involves monitoring emerging threats, providing real-time threat context, and collaborating with various teams to enhance security measures.

The ideal candidate will have a strong background in threat intelligence roles, familiarity with SIEMs, and solid communication skills. Certifications such as SANS/GIAC are needed, along with knowledge in connected devices.

Qualifications

  • Proven experience in a CTI, SOC, threat hunting, or cyber investigation role.
  • Deep knowledge of IT infrastructure, familiar with OT and IoT environments.
  • Strong analytical and investigative mindset with ability to connect data points.

Responsibilities

  • Continuously monitor OSINT, dark web, and threat feeds for emerging threats.
  • Collaborate with teams to enrich alerts and improve detection capabilities.
  • Produce actionable intelligence reports for technical and executive leadership.

Skills

Threat intelligence experience
Understanding of MITRE ATT&CK
Hands-on experience with SIEMs
Analytical mindset
Excellent communication skills

Education

Certifications such as SANS/GIAC, CompTIA CySA+

Tools

MISP
OpenCTI

Job description

Responsibilities
  • Continuously monitor OSINT, dark web, and threat feeds for emerging threats relevant to JLR.
  • Analyse TTPs of threat actors with a focus on automotive, manufacturing, and connected vehicle sectors.
  • Provide real‑time threat context and attribution during active incident investigations.
  • Collaborate with CDOC, SOC and detection engineering teams to enrich alerts and improve detection capabilities.
  • Produce high‑quality actionable intelligence reports tailored for both technical and executive leadership.
  • Maintain threat profiles, dashboards, and intelligence repositories to support strategic decision making.
  • Engage with industry peers, ISACs, and government bodies to share and receive threat intelligence.
  • Support JLR's participation in national and international cyber resilience initiatives.
  • Leverage and maintain threat intelligence platforms such as MISP, OpenCTI and integrate with security tooling.
  • Develop scripts and automation to streamline intelligence collection, enrichment and dissemination.
Required Skills
  • Proven experience in a CTI, SOC, threat hunting, or cyber investigation role.
  • Strong understanding of MITRE ATT&CK, NIST CSF, cyber kill chain, and threat modeling methodologies.
  • Hands‑on experience with threat intelligence platforms, SIEMs, and data enrichment tools.
  • Deep knowledge of IT infrastructure, with familiarity in OT and IoT environments, including SCADA/ICS and connected devices.
  • Strong analytical and investigative mindset with the ability to connect disparate data points into meaningful intelligence.
  • Excellent communication and presentation skills, capable of translating complex threats into business‑relevant insights.
  • Certifications such as SANS/GIAC, CompTIA CySA+, or equivalent.
  • Experience in automotive or manufacturing environments.
  • Knowledge of geopolitical and supply‑chain risks affecting cyber posture.
Nice‑to‑Have Skills
  • Proven experience in a CTI, SOC, threat hunting, or cyber investigation role.
  • Strong understanding of MITRE ATT&CK, NIST CSF, cyber kill chain, and threat modeling methodologies.
  • Hands‑on experience with threat intelligence platforms, SIEMs, and data enrichment tools.
  • Deep knowledge of IT infrastructure, with familiarity in OT and IoT environments, including SCADA/ICS and connected devices.
  • Strong analytical and investigative mindset with the ability to connect disparate data points into meaningful intelligence.
  • Excellent communication and presentation skills, capable of translating complex threats into business‑relevant insights.
  • Certifications such as SANS/GIAC, CompTIA CySA+, or equivalent.
  • Experience in automotive or manufacturing environments.
  • Knowledge of geopolitical and supply‑chain risks affecting cyber posture.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

Creative Artists Agency • Greater London

On-site
GBP 90,000 - 120,000
Cyber Security Architect
Cyber Security Architect

Tata Technologies • Gaydon

On-site
GBP 90,000 - 130,000
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
L3 SOC Analyst
L3 SOC Analyst

Saviynt • United Kingdom

On-site
GBP 60,000 - 80,000
Threat Intelligence Engineer
Threat Intelligence Engineer

Selby Jennings • Greater London

On-site
GBP 90,000 - 130,000
Threat Intelligence Production Lead
Threat Intelligence Production Lead

Accenture UK & Ireland • Greater London

Hybrid
GBP 90,000 - 130,000
Hands-On Cyber Security Engineer: Build, Automate, Protect
Hands-On Cyber Security Engineer: Build, Automate, Protect

Interact Software • Manchester

On-site
GBP 65,000 - 90,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Senior Security Consultant (Incident Response)
Senior Security Consultant (Incident Response)

LRQA • Birmingham

Hybrid
GBP 70,000 - 110,000